Change Cookie Consent Preferences

Privacy policy

Thank you for visiting our website white-sparrow.de and for your interest in our company.

The protection of your personal data, such as date of birth, name, telephone number, address, etc., is important to us.

The purpose of this privacy policy is to inform you about the processing of your personal data that we collect from you when you visit our website. Our data protection practice is in accordance with the legal regulations of the EU’s General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The following data protection declaration serves to fulfil the information obligations resulting from the GDPR. These can be found, for example, in Art. 13 and Art. 14 ff. GDPR.

Responsible person

The controller within the meaning of Art. 4 No. 7 GDPR is the person who alone or jointly with others determines the purposes and means of the processing of personal data.

With regard to our website, the responsible person is:

MKM Compliance GmbH
Leipziger Platz 9
10117 Berlin
Germany
E-mail: kontakt@mkm-compliance.de
Tel: +49 305 445 351 0

Provision of the website and creation of log files

Each time our website is accessed, our system automatically collects data and information from the device (e.g. computer, mobile phone, tablet, etc.) used to access it.

What personal data is collected and to what extent is it processed?

(1) Information about the browser type and version used;
(2) The operating system of the retrieval device;
(3) Host name of the accessing computer;
(4) The IP address of the retrieval device;
(5) Date and time of access;
(6) Websites and resources (images, files, other page content) accessed on our website;
(7) Websites from which the user’s system accessed our website (referrer tracking);
(8) Message whether the retrieval was successful;
(9) Amount of data transmitted

This data is stored in the log files of our system. This data is not stored together with the personal data of a specific user, so that individual site visitors cannot be identified.

Legal basis for the processing of personal data

Art. 6 para. 1 lit. f GDPR (legitimate interest). Our legitimate interest is to ensure the achievement of the purpose described below.

Purpose of the data processing

The temporary (automated) storage of the data is necessary for the course of a website visit to enable delivery of the website. The storage and processing of personal data is also carried out to maintain the compatibility of our website for as many visitors as possible and to combat abuse and eliminate malfunctions. For this purpose, it is necessary to log the technical data of the accessing computer in order to be able to react as early as possible to display errors, attacks on our IT systems and/or errors in the functionality of our website. In addition, we use the data to optimise the website and to generally ensure the security of our information technology systems.

Duration of storage

The deletion of the aforementioned technical data takes place as soon as they are no longer required to ensure the compatibility of the website for all visitors, but no later than 3 months after accessing our website.

Possibility of objection and deletion

You can object to the processing at any time in accordance with Article 21 of the GDPR and request the deletion of data in accordance with Article 17 of the GDPR. You can find out which rights you have and how to exercise them at the bottom of this privacy policy.

Special functions of the website

Our site offers you various functions, during the use of which personal data is collected, processed and stored by us. We explain below what happens to this data:

Callback service

  • What personal data is collected and to what extent is it processed?

    We will process the data you enter in our callback form, such as telephone number and name, to fulfil the following purpose.

  • Legal basis for the processing of personal data

    Art. 6 para. 1 lit. a GDPR (consent through clear confirming action or behaviour)

  • Purpose of the data processing

    The purpose of the data processing is the provision and implementation of the callback service or the fulfilment of the callback request.

  • Duration of storage

    The data will be deleted as soon as it is no longer required for processing your callback request.

  • Revocation and deletion option

    You can revoke your consent to contact us at any time in accordance with Art. 7 (3) GDPR. However, the processing carried out up to the time of the revocation remains unaffected by this. With regard to the other rights, we refer to the overview at the end of this data protection declaration.

  • Necessity of providing personal data

    All data entered by you in our callback form, in particular the entry written by you and further details such as your name / pseudonym or e-mail address, will be processed by us to fulfil the purpose stated below.

Contact form(s)

  • What personal data is collected and to what extent is it processed?

    We will process the data you have entered in the input mask of our contact forms to fulfil the purpose stated below.

  • Legal basis for the processing of personal data

    Art. 6 para. 1 lit. a GDPR (consent through clear confirming action or behaviour)

  • Purpose of the data processing

    We will only use the data recorded via our contact form or contact forms for processing the specific contact enquiry received through the contact form.

  • Duration of storage

    After processing your request, the collected data will be deleted immediately, unless there are legal retention periods.

  • Revocation and deletion option

    The revocation and deletion options are based on the general regulations on the right of revocation and deletion under data protection law described below in this data protection declaration.

  • Necessity of providing personal data

    The use of the contact forms is on a voluntary basis and is neither contractually nor legally required. You are not obliged to contact us via the contact form, but can also use the other contact options provided on our site. If you wish to use our contact form, you must fill in the fields marked as mandatory. If you do not fill in the required information on the contact form, you will either not be able to send the enquiry or we will unfortunately not be able to process your enquiry.

Appointment booking form

  • What personal data is collected and to what extent is it processed?

    We will process the data you enter on our appointment booking form to fulfil the purpose stated below.

  • Legal basis for the processing of personal data

    Art. 6 para. 1 lit. b GDPR (implementation of (pre)contractual measures)

  • Purpose of the data processing

    We will only use the data recorded via our appointment booking form to process appointment requests received through the appointment booking form.

  • Duration of storage

    Your appointment booking will be deleted by us immediately after the expiry of 12 months after the appointment was scheduled, insofar as no statutory retention obligations exist. We reserve the right to delete your data without giving reasons and without prior or subsequent information.

  • Possibility of objection and deletion

    You can find out what rights you have and how to exercise them at the bottom of this privacy statement.

  • Necessity of providing personal data

    Although the use of our appointment booking form is neither contractually nor legally required, it is necessary if you wish to book an appointment with us online. You must provide certain mandatory information for online booking. If you do not fill in the mandatory information completely, your appointment booking cannot be accepted or processed.

Statistical analysis of visits to this website – Webtracker

We collect, process and store the following data when this website or individual files on the website are accessed: IP address, website from which the file was accessed, name of the file, date and time of access, amount of data transferred and report on the success of the access (so-called web log). We use this access data exclusively in a non-personalised form for the continuous improvement of our website and for statistical purposes. We also use the following web trackers to evaluate visits to this website:

  • Google Tag Manager

    We use on our site the service Google Tag Manager of the company Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: https://www.google.com/. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF – https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

    The legal basis for the processing of personal data is your consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

    Google Tag Manager provides a technical platform for executing and bundling other web tools and web tracking programmes by means of so-called “tags”. in this context, Google Tag Manager stores cookies on your computer and analyses your surfing behaviour (so-called “tracking”), insofar as web tracking tools are executed using Google Tag Manager. The data generated by the “tags” are compiled, stored and processed by Google Tag Manager under a uniform user interface. All integrated “tags” are listed separately again in this data protection declaration. When you use our website with the integration of Google Tag Manager “tags” activated, data such as your IP address and your user activities in particular are transmitted to Google servers. The tracking tools used in Google Tag Manager ensure that the IP address is anonymised by Google Tag Manager before transmission by means of IP anonymisation of the source code. With Tag Manager, measured values from different service providers (Google and third-party providers) can be linked and evaluated on the basis of the so-called tag management. Google Tag Manager helps us to compile reports on website activity and to control the web tools of our website.

    For processing itself, the service or we collect the following data: Cookies, web tracking data, outgoing or incoming links, information generated by the integration and activation of JavaScript code on the website from Google Tag Manager and the web tools triggered by Google Tag Manager.

    you can access the provider’s certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

    You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

    For further information on the handling of transmitted data, please refer to the provider’s privacy policy at https://policies.google.com/privacy.

    The provider also offers an opt-out option at https://policies.google.com/privacy.

  • LinkedIn Analytics

    We use on our site the service LinkedIn Analytics of the company LinkedIn Ireland Unlimited Company, Wilton Place, 2 Dublin, Ireland, e-mail: info_impressum@cs.linkedin.com, website: https://www.linkedin.com/. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF – https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

    The legal basis for the processing of personal data is your consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

    The service is a website analytics tool that helps us understand user behaviour on our website. It automatically tracks activities such as clicks, scrolling and form completion without us having to implement any code. With the data generated, we can analyse exactly how visitors interact with our website and gain insights to optimise our online presence.

    You can access the provider’s certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

    You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

    For further information on the handling of transmitted data, please refer to the provider’s privacy policy at https://www.linkedin.com/legal/privacy-policy?trk=uno-reg-guest-home-privacy-policy.

    The provider also offers an opt-out option at https://www.linkedin.com/help/linkedin/answer/68763?lang=de.

  • Microsoft Advertising

    We use on our site the service Microsoft Advertising of the company Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, 18 Dublin , Ireland, e-mail: kunden@microsoft.com, website: https://www.microsoft.com/. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF – https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

    The legal basis for the processing of personal data is your consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

    Microsoft processes information about your interactions and activities to analyse your usage patterns in order to serve you targeted benefit- and interest-based advertising on the Microsoft Bing search engine and the Microsoft Audience Network using the UET-tag, which uses cookies to track your activities. The information collected is also used to target usage and interest-based advertising based on your usage. Details of the personal data processed in this way can be found at https://help.ads.microsoft.com/#apex/ads/de/53056/2/#exp6949. This data is stored for 390 days.

    The certification of the parent company Microsoft within the framework of the EU-US Data Privacy Framework can be found at https://www.dataprivacyframework.gov/list.

    You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

    For further information on the handling of transmitted data, please refer to the provider’s privacy policy at https://privacy.microsoft.com/de-de/privacystatement.

    The provider also offers an opt-out option at https://optout.networkadvertising.org/.

Integration of external web services and processing of data outside the EU

On our website, we use active content from external providers, so-called web services. When you visit our website, these external providers may receive personal information about your visit to our website. This may involve the processing of data outside the EU. You can prevent this by installing an appropriate browser plug-in or deactivating the execution of scripts in your browser. This may result in functional restrictions on websites that you visit.

We use the following external web services:

  • Calendly

    We use on our site the service Calendly of the company Calendly LLC, 1315 Peachtree St NE, GA 30309 Atlanta, United States, e-mail: support@calendly.com, website: https://calendly.com/. The transfer also takes place to a third country for which there is no adequacy decision by the Commission. Therefore, the usual level of protection for the GDPR cannot be guaranteed for the transfer, as it cannot be ruled out that in the third country, e.g. authorities can access the collected data.

    The legal basis for the processing of personal data is your consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

    The service supports us by providing an online calendar to record and manage appointments booked or reserved by you.

    You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

    For further information on the handling of transmitted data, please refer to the provider’s privacy policy at https://calendly.com/privacy.

  • LinkedIn

    We use on our site the service LinkedIn of the company LinkedIn Ireland Unlimited Company, Wilton Place, 2 Dublin, Ireland, e-mail: info_impressum@cs.linkedin.com, website: https://www.linkedin.com/. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF – https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

    The legal basis for the processing of personal data is your consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

    When using the Linkedin plugin, we establish a connection to the Linkedin platform in order to give logged-in Linkedin members the opportunity to interact with us.

    You can access the provider’s certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

    You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

    For further information on the handling of transmitted data, please refer to the provider’s privacy policy at https://www.linkedin.com/legal/privacy-policy?trk=uno-reg-guest-home-privacy-policy.

    The provider also offers an opt-out option at https://www.linkedin.com/help/linkedin/answer/68763?lang=de.

  • Rechtstextsnippet und Module

    We use on our site the service Rechtstextsnippet und Module of the company Website-Check GmbH, Beethovenstraße 24, 66111 Saarbrücken, Germany, e-mail: support@website-check.de, website: https://www.website-check.de/. Personal data is transmitted exclusively to servers in the European Union.

    The legal basis for the processing is Art. 6 para. 1 lit. c GDPR. The use of the service helps us to comply with our legal obligations.

    With the help of the service, the contents of our legal texts are reloaded on our website. The respective current legal texts are reloaded via the integration on our page. This integration may also be used to reload further technical modules with regard to the legal texts or legally required elements.

    You can find out what rights you have with regard to processing at the end of this privacy policy.

    For further information on the handling of transmitted data, please refer to the provider’s privacy policy at https://www.website-check.de/datenschutzerklaerung/.

  • Vimeo

    We use on our site the service Vimeo of the company Vimeo, Inc., 555 West 18th Street, 10011 New York, United States, e-mail: Privacy@vimeo.com, website: http://www.vimeo.com/. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF – https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

    The legal basis for the processing of personal data is your consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

    Videos from the Vimeo platform are integrated on our website via the Vimeo service.

    You can access the provider’s certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

    You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

    For further information on the handling of transmitted data, please refer to the provider’s privacy policy at https://vimeo.com/privacy.

    The provider also offers an opt-out option at https://vimeo.com/privacy.

  • WordPress

    We use on our site the service WordPress of the company Automattic Inc., 60 29th Street #343, CA 94110 San Francisco, United States, e-mail: help@wordpress.com, website: https://automattic.com/. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF – https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

    The legal basis for the processing of personal data is our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in achieving the purpose described below.

    WordPress is the technical system behind our website that runs our WordPress website. We need the integration so that we can show you our website and edit content.

    You can access the provider’s certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

    With regard to the processing, you have the right to object as set out in Art. 21. You can find more information at the end of this privacy policy.

    For further information on the handling of transmitted data, please refer to the provider’s privacy policy at https://automattic.com/privacy/.

Information about the use of cookies

  • What personal data is collected and to what extent is it processed?

    We integrate and use cookies on various pages to enable certain functions of our website and to integrate external web services. The so-called “cookies” are small text files that your browser can store on your access device. These text files contain a characteristic string that uniquely identifies the browser when you return to our website. The process of saving a cookie file is also referred to as “setting a cookie”. Cookies can be set both by the website itself and by external web services. Cookies are set by our website or external web services in order to maintain the full functionality of our website, to improve the user experience or to pursue the purpose stated with your consent. Cookie technology also allows us to recognise individual visitors by pseudonyms, e.g. a unique or random ID, so that we can provide more personalised services. Details are shown in the table below.

  • Legal basis for the processing of personal data

    Insofar as the cookies are processed on the basis of consent pursuant to Art. 6 para. 1 lit. a GDPR, this consent is also deemed to be consent within the meaning of Section 25 para. 1 TTDSG for the setting of the cookie on the user’s terminal device. Insofar as another legal basis is mentioned according to the GDPR (e.g. for the fulfilment of a contract or for the fulfilment of legal obligations), the storage or setting takes place on the basis of an exception according to Section 25 (2) TTDSG. This is the case “if the sole purpose of storing information in the end user’s terminal equipment or the sole purpose of accessing information already stored in the end user’s terminal equipment is to carry out the transmission of a message via a public telecommunications network” or “where the storage of information in the end-user’s terminal equipment or the access to information already stored in the end-user’s terminal equipment is strictly necessary to enable the provider of a telemedia service to provide a telemedia service explicitly requested by the user”. Which legal basis is relevant can be seen from the cookie table listed later in this point.

  • Purpose of the data processing

    The cookies are set by our website or the external web services in order to maintain the full functionality of our website, to improve the user-friendliness or to pursue the purpose stated with your consent. Cookie technology also allows us to recognise individual visitors by pseudonyms, e.g. an individual or random IDs, so that we can offer more personalised services. Details are provided in the table below.

  • Duration of storage

    Our cookies are stored until they are deleted in your browser or, if they are session cookies, until the session has expired. Details are listed in the following table.

  • Possibility of objection and removal

    You can set your browser according to your wishes so that the setting of cookies is generally prevented. You can then decide on a case-by-case basis whether to accept cookies or accept cookies in principle. Cookies can be used for various purposes, e.g. to recognise that your access device is already connected to our website (permanent cookies) or to save recently viewed offers (session cookies). If you have expressly given us permission to process your personal data, you can revoke this consent at any time. Please note that the lawfulness of the processing carried out on the basis of the consent until the revocation is not affected by this.

Cookie name Server Provider Purpose Legal basis Storage period Type
AnalyticsSyncHistory .linkedin.com LinkedIn The cookie used assigns an ID to the page visitor and determines statistical data on the page visitor’s website visits. This serves to individualise the advertising displayed to the user. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 30 days Marketing
MUID .bing.com Bing (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, 18 Dublin , Ireland) This cookie is used by Microsoft to assign a unique user ID to the site visitor. The cookie enables the tracking of page visitors on other websites offered by Microsoft by synchronising the ID. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 13 months Analytics
UserMatchHistory .linkedin.com LinkedIn This cookie assigns an ID to the page visitor. This ID is used to collect data on visitor behaviour on several websites in order to display individual advertising to the site visitor. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 30 days Marketing
__cfruid .calendly.com Calendly This cookie is part of the CDN services offered by Cloudflare. The CDN services allow us to speed up our website by creating server load balancing and to protect our server connection from abusive access by bots or other attacks. Art. 6 para. 1 lit. f GDPR (legitimate interests) Session Security
_gcl_au white-sparrow.de Google Tag Manager This cookie is used by Google AdSense to increase the efficiency of advertising. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 3 months Marketing
_uetsid .white-sparrow.de Microsoft Advertising This cookie assigns an ID to the page visitor. This ID is used to collect data on visitor behaviour on several websites in order to display individual advertising to the site visitor. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 24 hours Marketing
_uetvid .white-sparrow.de Microsoft Advertising This cookie assigns an ID to the page visitor. This ID is used to collect data on visitor behaviour on several websites in order to display individual advertising to the site visitor. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 13 months Marketing
bscookie .linkedin.com LinkedIn The cookie used assigns an ID to the page visitor and determines statistical data on the page visitor’s website visits. This serves to individualise the advertising displayed to the user. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 12 months Marketing
bscookie .www.linkedin.com LinkedIn The cookie used assigns an ID to the page visitor and determines statistical data on the page visitor’s website visits. This serves to individualise the advertising displayed to the user. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 12 months Marketing
cf_bm .calendly.com Calendly This cookie is used to confirm that the visitor comes from a known computer. This allows security barriers to be overcome and loading times to be accelerated. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 30 minutes Configuration
li_gc .linkedin.com LinkedIn This cookie is used to store guests’ consent to the use of non-mandatory cookies. Art. 6 para. 1 lit. c GDPR (fulfilment of legal obligation) approx. 6 months Cookie banner
li_sugr .linkedin.com LinkedIn This cookie is used to store browser data in order to personalise future advertising and tailor it to the country of the site visitor. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 3 months Marketing
lidc .linkedin.com LinkedIn This cookie assigns an ID to the page visitor. This ID is used to collect data on visitor behaviour on several websites in order to display individual advertising to the site visitor. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) approx. 24 hours Marketing
mkm_cbconsent white-sparrow.de Website operator](#responsible-entity) The cookie enables us to fulfil our legal obligation with regard to obtaining legally required consents. Through the cookie banner, we store the settings and consents you have made. Art. 6 para. 1 lit. c GDPR (fulfilment of legal obligation) Session Cookie banner
wp-wpml_current_language white-sparrow.de Website operator](#responsible-entity) The cookie stores language settings or recognises the browser language and directs the user of this website directly to the appropriate multilingual content. Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (consent) Session Configuration

Data security and data protection, communication by e-mail

Your personal data is protected by technical and organisational measures during collection, storage and processing so that it is not accessible to third parties. In the case of unencrypted communication by e-mail, we cannot guarantee complete data security on the transmission path to our IT systems, so that we recommend encrypted communication or the postal service for information requiring a high level of confidentiality.

Automatic e-mail archiving

  • Scope of the processing of personal data

    We expressly point out that our mail system has an automated archiving procedure. All incoming and outgoing e-mails are digitally archived in an audit-proof manner.

  • Legal basis for the processing of personal data

    Art. 6 para. 1 lit. c GDPR (legal obligation). The legal obligation consists of compliance with tax and commercial law requirements (e.g. §§ 146, 147 AO, §§ 238, 257 HGB).

  • Purpose of the data processing

    The purpose of archiving is to comply with tax law requirements (e.g. §§ 146, 147 AO – obligation to retain e-mails of relevance to tax law) and commercial law requirements (e.g. §§ 238, 257 HGB – obligation to archive business correspondence).

  • Duration of storage

    Our mail communication is stored until the expiry of storage obligations under tax and commercial law. The storage period can be up to 10 years.

  • Possibility of objection and deletion

    You can object to the processing at any time in accordance with Article 21 of the GDPR and request the deletion of data in accordance with Article 17 of the GDPR. You can find out which rights you have and how to exercise them at the bottom of this privacy policy.

  • Dealing with application documents

    We would also like to point out that we only consider application documents in PDF file format. Zipped files (WinZip, WinRAR, 7Zip, etc.) are filtered out by our security systems and will not be delivered. We do not consider applications in Word file format and other file formats and delete them unread. Please note that application documents sent by e-mail without encryption may be opened by third parties before they reach our IT systems. We assume that we may also reply to unencrypted application e-mails unencrypted. If you do not wish this, please let us know in your application e-mail.

Right to information and correction requests – Deletion & restriction of data – Revocation of consent – Right to object

Right to information

You have the right to request confirmation as to whether we are processing your personal data. If this is the case, you have the right to be informed about the information named in Art. 15 (1) of the GDPR, insofar as the rights and freedoms of other persons are not affected (cf. Art. 15 (4) of the GDPR). We will also be happy to provide you with a copy of the data.

Right of rectification

In accordance with Article 16 of the GDPR, you have the right to have any incorrect personal data stored with us (e.g. address, name, etc.) corrected at any time. You can also request that the data stored with us be completed at any time. A corresponding adjustment will be made immediately.

Right to erasure

Pursuant to Art. 17 (1) of the GDPR, you have the right to demand that we delete the personal data we have collected about you if

  • the data is either no longer required;
  • the legal basis for the processing has ceased to exist without replacement due to the withdrawal of your consent;
  • You have objected to the processing and there are no legitimate grounds for processing;
  • Your data is processed unlawfully;
  • a legal obligation requires this or a collection pursuant to Art. 8 (1) GDPR has taken place.

Pursuant to Article 17 (3) of the GDPR, this right does not exist if

  • processing is necessary for the exercise of the right to freedom of expression and information;
  • Your data have been collected on the basis of a legal obligation;
  • processing is necessary for reasons of public interest;
  • the data are necessary for the assertion, exercise or defence of legal claims.

Right to restriction of processing

According to Art. 18 (1) GDPR, you have the right in individual cases to demand the restriction of the processing of your personal data.

This is the case when

  • the accuracy of the personal data is disputed by you;
  • the processing is unlawful and you do not consent to its erasure;
  • the data is no longer needed for the purpose of processing, but the collected data is used for the assertion, exercise or defence of legal claims;
  • an objection to the processing has been lodged pursuant to Art. 21 (1) GDPR and it is still unclear which interests prevail.

Right of withdrawal

If you have given us express consent to process your personal data (Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR), you can revoke this consent at any time. Please note that the lawfulness of the processing carried out on the basis of the consent until the revocation is not affected by this.

Right to object

In accordance with Art. 21 of the GDPR, you have the right to object at any time to the processing of personal data relating to you that has been collected on the basis of Art. 6 (1) (f) (in the context of a legitimate interest). You only have this right if there are special circumstances against the storage and processing.

How do you exercise your rights?

You can exercise your rights at any time by contacting us using the contact details below:

MKM Compliance GmbH
Leipziger Platz 9
10117 Berlin
Germany
E-mail: kontakt@mkm-compliance.de
Tel: +49 305 445 351 0

Right to data portability

Pursuant to Article 20 of the GDPR, you have a right to the transfer of personal data relating to you. We will provide the data in a structured, common and machine-readable format. The data can be sent either to you or to a person responsible named by you.

We provide you with the following data upon request pursuant to Art. 20 para. 1 GDPR:

  • Data collected on the basis of explicit consent pursuant to Art. 6 (1) lit. a GDPR or Art. 9 (2) lit. a GDPR;
  • Data that we have received from you in accordance with Art. 6 Para. 1 lit. b GDPR within the scope of existing contracts;
  • Data that has been processed within the scope of an automated procedure.

We will transfer the personal data directly to a data controller of your choice as far as this is technically feasible. Please note that we are not permitted to transfer data that interferes with the freedoms and rights of other persons pursuant to Art. 20 (4) of the GDPR.

Right of appeal to the supervisory authority pursuant to Art. 77 para. 1 GDPR

If you suspect that your data is being processed illegally on our site, you can of course have the issue clarified by the courts at any time. In addition, any other legal option is open to you. Irrespective of this, you have the option of contacting a supervisory authority in accordance with Article 77 (1) of the GDPR. The right of complaint pursuant to Art. 77 GDPR is available to you in the EU Member State of your place of residence, your place of work and/or the place of the alleged infringement, i.e. you can choose the supervisory authority to which you turn from the above-mentioned places. The supervisory authority to which the complaint has been submitted will then inform you of the status and outcome of your submission, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.